Hey everyone, I got a question from a client I can't anser by myself. I found similar posts, but they don't help me in this case, sadly.
We have 205 APs there and use Radius Authentication, we have to SSIDs there, one is Internet-only, one is Internal-and-Internet (not the real names). The access is controlled via User Groups in AD.
He wants to have one SSID only, and the AP should determine wether it's a Client who is allowed to go to Internet-only, or Internal-and-Internet, by checking if the client has a certificate installed.
This way all mobile clients with a AD user would drop to, lets say VLAN 100, because they have no certificate installed, and all Notebooks (with certificate and user) would go to VLAN 200.
My biggest and first question: Is this possible with Instant-APs at all?
Also, this is a side Questions: My APs suddenly drop the config from time to time. Not everything, just certain thing (Radius IP is not the new radius, but the one I had previously, Guest SSID was hidden and disabled, suddenly it is propagated again and working) This stuff is weird.
Thanks in advance guys!